Privacy Policy
Last updated: 6 October 2026
This Privacy Policy explains how Trivor Technologies Pte. Ltd. ("Trivor", "we", "us") handles personal information collected through trivor.io and the Trivor platform (together, the "Service"). We are based in Singapore and follow the Personal Data Protection Act 2012 ("PDPA").
If you use Trivor as a member of an organisation's workspace, that organisation decides which data is connected to Trivor and how it is used. In that case we process workspace data on the organisation's behalf, and its own privacy policy also applies to you.
Information we collect
Information you give us
- Contact details. Your name, email address, company, team size and message when you request a demo or write to us.
- Account details. Your name and email address, received from Google or Microsoft when you sign in with them, plus the workspace and teams you belong to and your role in them. We do not receive or store your Google or Microsoft password.
- Your content. The messages you send to Trivor, the files you upload, and what Trivor produces for you, such as answers, files, dashboards and automations.
- Memory. Trivor can remember facts and preferences from your conversations so that later tasks start with the right context.
Information from accounts you connect
You can connect third-party accounts to Trivor, such as email, calendar, file storage, CRM, code hosting and advertising accounts. When you do, Trivor accesses only the categories of data you authorise and uses them only to carry out what you ask. Content retrieved from a connected account can be kept in your conversations, files and memory.
Trivor's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information collected automatically
- Technical data. IP address, browser and device type, and the times you access the Service, recorded in our server and security logs.
- Usage data. The actions you and Trivor take on the platform, including which tools ran and how much of the Service you used.
- Task logs. Records of the steps Trivor takes to complete your requests, kept for debugging and security purposes.
- Sandbox data. When Trivor runs code for you it does so in an isolated environment. We keep the files, commands and outputs from those runs so that work can continue and problems can be diagnosed.
We do not use advertising cookies or third-party analytics. The Service stores only what it needs to keep you signed in and remember your settings in your browser. Our demo request form uses Cloudflare Turnstile to block automated submissions.
How we use information
We use personal information to:
- provide the Service, including sending your requests and the relevant content to the AI models that generate Trivor's responses;
- carry out actions in your connected accounts when you ask for them;
- keep your account, workspace and teams working, and send you invitations, notifications and service messages;
- reply to demo requests, questions and support requests;
- keep the Service secure, investigate problems and prevent abuse;
- measure usage of the Service;
- comply with the law and enforce our terms.
We do not sell personal information.
AI models and your data
We do not use your content, your memory or data from your connected accounts to train AI models.
To generate responses, Trivor sends your request and the relevant content to the AI model providers we work with. They process it to return a response to us and do not use it to train their models.
If you add your own API key for an AI model provider, your requests and content are sent to that provider under your own agreement with it, and its terms and privacy policy apply.
AI-generated output can be inaccurate. Please review it before relying on it.
How we share information
We share personal information only with:
- Service providers that host and operate the Service for us, including cloud hosting, network security and email delivery.
- AI model providers that process your requests to generate responses, including any provider you add with your own API key.
- Web search providers, which receive the search queries Trivor runs for you.
- Third parties you choose, such as a connected account in which you ask Trivor to take an action.
- Other members of your workspace. Content you share with a team or a person is visible to them. Workspace administrators manage members, teams and workspace settings such as connected services and AI models.
- Professional advisers, such as lawyers and auditors, where needed for their services.
- Authorities, where the law requires it.
- A successor business, if Trivor is involved in a merger, acquisition or sale of assets.
Retention
We keep personal information for as long as your account or workspace is active, or as long as needed for the purposes above. You can ask us to delete your account or your content, and we will delete it within 30 days unless the law requires us to keep it. Backups expire on a rolling schedule within 30 days. Demo requests are kept for 24 months after our last contact with you.
If you belong to an organisation's workspace, the organisation decides how long workspace data is kept.
Your choices and rights
- Access and correction. You can ask for a copy of the personal information we hold about you and ask us to correct it.
- Withdrawing consent. You can withdraw your consent to our use of your personal information. Some parts of the Service may stop working if you do.
- Connected accounts. You can disconnect an account at any time in your settings. This stops future access but does not delete content already saved in your conversations, files or memory.
- Deletion. You can ask us to delete your account or your content.
To make a request, email dpo@trivor.io. We may need to confirm your identity first. We respond as soon as we reasonably can, and if we cannot respond within 30 days we will tell you when we will. If you are a member of an organisation's workspace, please contact your workspace administrator first.
Security
We protect personal information with measures that include encryption in transit and at rest, isolated environments for code execution, separation of each workspace's data, least-privilege access, and multi-factor authentication on administrative accounts. No system is completely secure. If a data breach occurs, we will notify the Personal Data Protection Commission and affected individuals where the law requires it.
International transfers
The Service is hosted in Singapore. Some of our service providers, including AI model providers, process information in other countries. Where we transfer personal information outside Singapore, we take steps to ensure it receives a standard of protection comparable to the PDPA.
Children
The Service is intended for business use and is not directed at anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
Other sites and services
The Service may link to, or act in, websites and services run by others. Their own privacy policies apply to what they do with your information.
Changes to this policy
We may update this Privacy Policy. We will post the new version here and update the date at the top. If a change is significant, we will notify you by email or in the Service.
Contact us
We have appointed a Data Protection Officer. For any question, request or complaint about this Privacy Policy, email dpo@trivor.io.